CVE-2018-1821: IBM Operational Decision Manager
Critical severity, CVSS 9.1. EPSS: 15.8% chance of exploitation in the next 30 days.
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150170.
Affected products
- IBM Operational Decision Manager: from 8.6.0.0, before 8.6.0.3 (fixed in 8.6.0.3); from 8.7.0.0, before 8.7.1.2 (fixed in 8.7.1.2); from 8.8.0.0, before 8.8.1.3 (fixed in 8.8.1.3); from 8.9.0.0, before 8.9.2.1 (fixed in 8.9.2.1)
Published 2018-12-13. Last modified 2026-06-17.